Self XSS : Grab Cookies Tricking Users Into Running Malicious Code

Self XSS attack using bit.ly to grab cookies tricking users into running malicious code.

How it works?

It is a social engineering attack used to gain control of victims’ web accounts by tricking users into copying and pasting malicious content into their browsers.

Since Web browser vendors and web sites have taken steps to mitigate this attack by blocking pasting javascript tag, I figure out a way of doing that using Bit.ly, so we can create a redirect pointing to “website.com/javascript:malicious_code”.

If the user is tricked to run the javascript code after “website.com/” the cookies of its authenticated/logged session of website.com will be sent to the attacker.

Features:

Port Forwarding using Ngrok and shortner using Bitly.com (Register for free)

Also Read – Top 5 Reasons Why You Need a Custom E-commerce Website in 2020

Requirement

https://bitly.com account (Register for free)

Disclaimer:

Usage of Self-XSS for attacking targets without prior mutual consent is illegal. It’s the end user’s responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

Usage:

git clone https://github.com/thelinuxchoice/self-xss
cd self-xss
bash self-xss.sh

R K

Recent Posts

Admin Panel Dorks : A Complete List of Google Dorks

Introduction Google Dorking is a technique where advanced search operators are used to uncover information…

4 days ago

Best Linux Distros in 2026

Linux is renowned for its versatility, open-source nature, and security. Whether you're a beginner, developer,…

4 days ago

Top 10 Cyber Insurance Companies in 2026

Cyber insurance helps businesses and individuals mitigate financial losses from data breaches, ransomware, extortion, legal…

4 days ago

Ransomware Incident Response

Ransomware is one of the most dangerous and destructive forms of cybercrime today. With cybercriminals…

4 days ago

Best Social Media Search Engines and Tools for 2026

Social media is a key part of our daily lives, with millions of users sharing…

4 days ago

How to Remove Your Personal Information from Data Broker Websites (2026 Guide)

What Are Data Brokers? Data brokers are companies that collect, aggregate, and sell personal information,…

4 days ago